CRITICAL
CVE-2026-90605
CVSS
9.9
Description
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Weakness (CWE)
CWE-119
Memory Buffer Bounds Error
CWE-120
Classic Buffer Overflow
EPSS Score
0.47%
Probability of exploitation in next 30 days
39.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.